Subscribe2 <= 10.45 - Reflected Cross-Site Scripting
medium
The Subscribe2 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 10.45 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tric...
- CVSS:
- 6.1
- Affected:
- up to 10.45
- Fixed in:
- 10.46
- Disclosed:
- Aug 3, 2026
CVE-2026-14331 on NVD →
Subscribe2 – Form, Email Subscribers & Newsletters [subscribe2] <= 10.44 (unfixed)
unknown
[en] Missing Authorization vulnerability in weDevs Subscribe2 subscribe2 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subscribe2: from n/a through <= 10.44.
- Affected:
- up to 10.44
- Fix:
- No patched version reported
- Disclosed:
- Feb 20, 2026
CVE-2026-24944 on NVD →
Subscribe2 <= 10.44 - Missing Authorization
medium
The Subscribe2 – Form, Email Subscribers & Newsletters plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 10.44. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 10.44
- Fixed in:
- 10.45
- Disclosed:
- Feb 3, 2026
CVE-2026-24944 on NVD →
Subscribe2 – Form, Email Subscribers & Newsletters [subscribe2] < 10.44
unknown
[en] The Subscribe2 – Form, Email Subscribers & Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ip parameter in all versions up to, and including, 10.43 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitr...
- Affected:
- up to 10.44
- Fixed in:
- 10.44
- Disclosed:
- Feb 19, 2025
CVE-2024-11582 on NVD →
Subscribe2 – Form, Email Subscribers & Newsletters <= 10.43 - Unauthenticated Stored Cross-Site Scripting via IP Parameter
high
The Subscribe2 – Form, Email Subscribers & Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ip parameter in all versions up to, and including, 10.43 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary w...
- CVSS:
- 7.2
- Affected:
- up to 10.43
- Fixed in:
- 10.44
- Disclosed:
- Feb 18, 2025
CVE-2024-11582 on NVD →
Appsero <= 2.0.0 - Missing Authorization via handle_optin_optout
medium
The Appsero analytics tool used in several plugins is vulnerable to unauthorized modification of data due to a missing capability check on the handle_optin_optout function in versions up to, and including, 2.0.0. This makes it possible for unauthenticated attackers to opt-in or opt-out of tracking. This was patched in...
- CVSS:
- 4.3
- Affected:
- up to 10.42
- Fixed in:
- 10.43
- Disclosed:
- Apr 11, 2024
CVE-2024-32110 on NVD →
Subscribe2 – Form, Email Subscribers & Newsletters [subscribe2] < 10.41
unknown
[en] The Subscribe2 plugin for WordPress is vulnerable to unauthorized access to email functionality due to a missing capability check when sending test emails in versions up to, and including, 10.40. This makes it possible for author-level attackers to send emails with arbitrary content and attachments to site users.
- Affected:
- up to 10.41
- Fixed in:
- 10.41
- Disclosed:
- Jun 28, 2023
CVE-2023-1844 on NVD →
Subscribe2 – Form, Email Subscribers & Newsletters [subscribe2] < 10.41
unknown
[en] The Subscribe2 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 10.40. This is due to missing or incorrect nonce validation when sending test emails. This makes it possible for unauthenticated attackers to send test emails with custom content to users on sites runn...
- Affected:
- up to 10.41
- Fixed in:
- 10.41
- Disclosed:
- Jun 28, 2023
CVE-2023-3407 on NVD →
Subscribe2 <= 10.40 - Missing Authorization
medium
The Subscribe2 plugin for WordPress is vulnerable to unauthorized access to email functionality due to a missing capability check when sending test emails in versions up to, and including, 10.40. This makes it possible for author-level attackers to send emails with arbitrary content and attachments to site users.
- CVSS:
- 4.3
- Affected:
- up to 10.40
- Fixed in:
- 10.41
- Disclosed:
- Jun 26, 2023
CVE-2023-1844 on NVD →
Subscribe2 <= 10.40 - Cross-Site Request Forgery
medium
The Subscribe2 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 10.40. This is due to missing or incorrect nonce validation when sending test emails. This makes it possible for unauthenticated attackers to send test emails with custom content to users on sites running a...
- CVSS:
- 4.3
- Affected:
- up to 10.40
- Fixed in:
- 10.41
- Disclosed:
- Jun 26, 2023
CVE-2023-3407 on NVD →
Subscribe2 – Form, Email Subscribers & Newsletters [subscribe2] < 10.38
unknown
[en] The Subscribe2 WordPress plugin before 10.38 does not have CSRF check when deleting users, which could allow attackers to make a logged in admin delete arbitrary users by knowing their email via a CSRF attack.
- Affected:
- up to 10.38
- Fixed in:
- 10.38
- Disclosed:
- Jan 16, 2023
CVE-2022-4309 on NVD →
Subscribe2 <= 10.37 - Cross-Site Request Forgery
high
The Subscribe2 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 10.37. This is due to missing or incorrect nonce validation on the process_bulk_action function. This makes it possible for unauthenticated attackers to delete users, via forged request granted they can tri...
- CVSS:
- 7.1
- Affected:
- up to 10.37
- Fixed in:
- 10.38
- Disclosed:
- Dec 22, 2022
CVE-2022-4309 on NVD →
Appsero <= 1.2.1 - Missing Authorization
medium
The Appsero analytics tool used in several plugins is vulnerable to authorization bypass due to a missing capability check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.1. This makes it possible for authenticated attackers, with subscriber-level permissio...
- CVSS:
- 4.3
- Affected:
- up to 10.37
- Fixed in:
- 10.38
- Disclosed:
- Dec 16, 2022
Appsero <= 1.2.0 - Cross-Site Request Forgery
medium
The Appsero analytics tool used in several plugins is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.0. This makes it possible for unauthenticated attackers to invoke this function inten...
- CVSS:
- 4.3
- Affected:
- up to 10.37
- Fixed in:
- 10.38
- Disclosed:
- Dec 14, 2022
CVE-2022-47150 on NVD →
Subscribe2 – Form, Email Subscribers & Newsletters [subscribe2] < 10.38
unknown
The Appsero analytics tool used in several plugins is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.0. This makes it possible for unauthenticated attackers to invoke this function inten...
- Affected:
- up to 10.38
- Fixed in:
- 10.38
- Disclosed:
- Dec 14, 2022
Subscribe2 – Form, Email Subscribers & Newsletters [subscribe2] < 10.16
unknown
[en] Cross-site scripting (XSS) vulnerability in class-s2-list-table.php in the Subscribe2 plugin before 10.16 for WordPress allows remote attackers to inject arbitrary web script or HTML via the ip parameter.
- Affected:
- up to 10.16
- Fixed in:
- 10.16
- Disclosed:
- Mar 29, 2018
CVE-2014-6604 on NVD →
Subscribe2 – Form, Email Subscribers & Newsletters [subscribe2] < 8.1
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update plugin.
- Affected:
- up to 8.1
- Fixed in:
- 8.1
- Disclosed:
- May 15, 2015
Subscribe2 – Form, Email Subscribers & Newsletters <= 10.15 - Stored Cross-Site Scripting
medium
The Subscribe2 – Form, Email Subscribers & Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REMOTE_ADDR value in versions up to, and including, 10.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with subscriber, or h...
- CVSS:
- 6.1
- Affected:
- up to 10.16
- Fixed in:
- 10.16
- Disclosed:
- Oct 1, 2014
CVE-2014-6604 on NVD →
Subscribe2 – Form, Email Subscribers & Newsletters < 8.1 - Multiple Cross-Site Scripting
high
The Subscribe2 – Form, Email Subscribers & Newsletters plugin for WordPress is vulnerable to Multiple Cross-Site Scripting via several parameters in versions before 8.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a vict...
- CVSS:
- 7.1
- Affected:
- up to 8.1
- Fixed in:
- 8.1
- Disclosed:
- Aug 1, 2014
Subscribe2 – Form, Email Subscribers & Newsletters [subscribe2] < 8.1
unknown
The Subscribe2 – Form, Email Subscribers & Newsletters plugin for WordPress is vulnerable to Multiple Cross-Site Scripting via several parameters in versions before 8.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a vict...
- Affected:
- up to 8.1
- Fixed in:
- 8.1
- Disclosed:
- Aug 1, 2014
Subscribe2 – Form, Email Subscribers & Newsletters [subscribe2] < 10.38
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 10.38
- Fixed in:
- 10.38
CVE-2022-47150 on NVD →
Subscribe2 – Form, Email Subscribers & Newsletters [subscribe2] < 8.1
unknown
The Subscribe2 – Form, Email Subscribers & Newsletters WordPress plugin was affected by a Cross Site Scripting security vulnerability.
- Affected:
- up to 8.1
- Fixed in:
- 8.1
Subscribe2 – Form, Email Subscribers & Newsletters [subscribe2] < 10.43
unknown
- Affected:
- up to 10.43
- Fixed in:
- 10.43
CVE-2024-32110 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database